• Synology has issued an urgent security update for its DiskStation Manager (DSM) software to address a critical vulnerability. If left unpatched, this flaw could allow unauthenticated remote attackers to execute arbitrary commands on affected network-attached storage (NAS) devices. Tracked under security advisory Synology-SA-26:03, this ongoing security event requires immediate attention from system administrators to protect […]

    The post Synology DiskStation Manager Vulnerability Puts Users at Risk of Remote Command Execution Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake npm install messages are the latest social engineering trick in the open source supply chain, with attackers abusing npm post‑install scripts to silently deploy a crypto‑stealing remote access trojan (RAT) in what ReversingLabs is calling the “Ghost campaign.” By wrapping their payloads in realistic but entirely bogus npm install logs, the threat actors turn […]

    The post Fake npm Install Messages Conceal RAT Malware in New Open Source Supply Chain Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • HUNTSVILLE, Ala.—Army leaders often say they want to stop using million-dollar missiles to shoot down thousand-dollar drones. One of the solutions may be cheap munitions the service already has.

    While the Army is leading an interagency task force to source dedicated counter-drone systems, the Capability Program Executive for ammunition and energetics is taking a look at the Army’s existing rounds to make them capable of shooting down much smaller targets.

    “We all know how important missiles are to the fight. We see it in the news. But there's also a point where missiles can't get after every munition, every threat, so we need to supplement that with something that we already have within our formations,” Kaitlyn Tani, deputy project manager at Maneuver Ammunition systems, said Wednesday at the AUSA Global Force Symposium

    There has already been demonstrated success in using bullets against drones, she said, particularly ones like the XM121 High Explosive Proximity round, a 30mm bullet that only needs to get near a target to take it out with its blast radius. 

    There are a handful of other systems that can use this proximity fuze technology and put it into weapon systems that aren’t made to shoot tiny quadcopters in the sky, but could do it with a round that only needs to get close. 

    “We're taking your Bradley fighting vehicle and [making it] counter-UAS capable by using the armament that is already on the system,” Tani said. “We're taking the infantry soldiers who already have Mk-19s within their squad and providing them with counter-UAS capability.”

    There’s also the potential to take some larger rounds, like indirect fire munitions designed to be launched at coordinates rather than targeted using the sight of a gun, and strapping them onto drones.

    “So we're definitely looking at all of our legacy munitions,” said Col. Vinson Morris, project manager for Close Combat Systems.

    To do that, Morris said, they have to tweak the rounds to use them with a UAS, as they’re designed to be fired from a ground-based launcher that does the propelling toward a target.

    “We see the first iteration of this potentially being a legacy mortar or legacy artillery [round] dropped from a UAS,” he said. 

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russian law enforcement agencies have successfully apprehended the suspected administrator of LeakBase, a prominent international cybercrime forum. The arrest, executed by officers from the Russian Ministry of Internal Affairs (MVD) alongside regional security services in Rostov, marks a significant disruption to the global underground trade of stolen data. The suspect, a resident of Taganrog, is […]

    The post LeakBase Forum Admin Arrested by Russian Authorities in Global Cybercrime Operation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls. “Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data,” Sansec said in a report published this week. The attack,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Aqua Security’s vulnerability scanner, Trivy, suffered a sophisticated CI/CD supply chain compromise. The threat actor, identified as TeamPCP, leveraged prior incomplete remediation to inject credential-stealing malware into official releases. This incident, tracked as CVE-2026-33634, successfully weaponized a trusted security tool against the organizations relying on it to stay safe. This visualizes the attack propagation timeline […]

    The post Microsoft Unveils New Guidance to Detect and Defend Against Trivy Supply Chain Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A large-scale phishing campaign is actively targeting developers on GitHub by abusing the platform’s Discussions feature to distribute fake Visual Studio Code (VS Code) security alerts. The campaign appears highly coordinated, with thousands of near-identical posts discovered across multiple repositories, indicating automated mass exploitation rather than isolated abuse. Attackers are creating GitHub Discussions with alarming […]

    The post Fake VS Code Security Alerts on GitHub Spread Malware in Massive Phishing Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cisco has released critical security updates to address a maximum-severity vulnerability affecting its Secure Firewall Management Center (FMC) Software. Tracked under the identifier CVE-2026-20131, this flaw carries a perfect CVSS base score of 10.0 and allows unauthenticated, remote attackers to execute arbitrary code. The situation is particularly urgent as the company has confirmed that threat […]

    The post Cisco Secure Firewall Vulnerability Exposes Systems to Remote Code Execution by Attackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The Node.js project issued a critical security update for its Long-Term Support (LTS) branch, marking version 20.20.2 ‘Iron’ as a security release. This urgent patch addresses seven distinct vulnerabilities impacting TLS error handling, HTTP/2 flow control, cryptographic timing, and permission models. Several of these issues can be exploited remotely without authentication, posing an immediate risk […]

    The post Node.js Releases Urgent Patches for Multiple Vulnerabilities Exposing Systems to DoS and Crashes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The debate about lethal autonomy—core to the Trump administration’s fight with Anthropic—obscures a deeper danger of the Pentagon’s rapid adoption of commercial AI tools: they might weaken the U.S. military’s ability to tell fact from fiction.

    New research suggests that relying on AI to do various tasks can erode one's native ability to do them. Military commanders are taking note. 

    “The more you use AI, the more you will use your brain in a different way,” said French Adm. Pierre Vandier, NATO Supreme Allied Commander for Transformation, in a conversation in Defense One’s "State of Defense" series. “And so [we need to] be able to have some oversight, to be able to critique what we see from AI, and to be sure you are not fooled by a sort of false presentation of things. It's something we need to take care of.”

    But there is scant evidence that the Pentagon, in its rush to deploy AI tools, is taking steps to keep its users sharp—or even to monitor the effects of AI.

    “Because of the pace and the urgency associated with deploying these models, maybe that hasn’t been put in place,” said one former senior military official who worked to deploy AI in combat settings.

    In the meantime, the pressure to use AI tools is only growing.

    “Especially as you get deeper into any conflict, there will be more and more pressure to find more targets. That happens in every conflict as well. After two weeks, you're sort of going through your delivery target list. Now you're demanding targets. Well, how fast can you generate targets?” the former senior military official said.

    A cognitive trap

    A growing body of research shows that wide use of large language models can undermine human thought and communication.

    For example, it can homogenize thinking among users, reinforcing “dominant styles while marginalizing alternative voices and reasoning strategies,” according to an Air Force Research Laboratory paper published earlier this month in the journal Cell.

    This presents at least two problems for the military, said Morteza Dehghani, a University of Southern California computer science professor who helped write the paper. In the moment, “it washes away signals about who the author is,” and therefore eliminates important context for evaluating data. And over time, it can stifle critical thinking. 

    “Because these models are optimized for the most likely and ‘idealized’ responses, they often enforce a linear, ‘Chain-of-Thought’ reasoning style,” Dehghani wrote in an email. “This can disincentivize experienced analysts from employing the non-linear, intuitive, or ‘gut feeling’ strategies that are essential for identifying rare exceptions or navigating complex, non-standard intelligence scenarios.”

    Similarly, researchers at Wharton found in January that people using LLMs spend less and less time scrutinizing results for accuracy or employing their own judgment. They found that users rely on the AI’s judgement even when they know it’s wrong, a phenomenon the authors call “cognitive surrender.”

    And a February paper from Princeton found that the way LLMs speak to users—referred to as “sycophantic AI”—instills a false sense of confidence and isolates people within preconceived biases: “Our results show that the default interactions of a popular chatbot resemble the effects of providing people with confirmatory evidence, increasing confidence but bringing them no closer to the truth.”

    Who is driving?

    The military is aware of at least some dimensions of the problem. Speaking on a March 6 podcast, Pentagon research-and-engineering chief Emil Michael said that his core concern about Anthropic—which President Trump has barred from use by the federal government—was that military users might become too dependent on a single untrustworthy tool.

    “Maybe it's a rogue developer who could poison the model to make it not do what you want at the time, or sort of trick you because you have to trick it. I mean, all these things that we know when we worry about models that hallucinate purposefully or do not follow instructions,” Michael said.

    Anthropic had similar concerns: that its tools might be used by people untrained to properly evaluate its output. One company official said their chief worry was that they had not validated that the model could be used reliably for compiling targeting lists. Worse, they had no way of knowing how the military was putting their tools to use. For example, Anthropic officials only learned after the fact that their tools had been used to plan the Jan. 3 raid into Venezuela.

    The Pentagon has since declared Anthropic products a supply-chain risk and is working to replace them, though they are still in use by military planners, including in the Middle East.

    A former senior official described it as “a serious governance question.” Frontier AI companies like OpenAI, Anthropic, Google, and xAI cannot provide the in-depth support required for military units to understand the conditions under which these tools are used.

    “It's almost becoming a journey of discovery for the government,” the former senior military official said. “Are there people on site from these companies helping the day-to-day user? My guess is, if there are, there may be only one or two of them.”

    ]]>

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶